[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-19685/network-manager

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 05:57:23 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a14120c6 by Salvatore Bonaccorso at 2026-09-03T06:55:12+02:00
Update status for CVE-2026-19685/network-manager

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11985,7 +11985,7 @@ CVE-2026-74580 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
 CVE-2026-19685 (NetworkManager did not apply the private_user restriction to the 802-1 ...)
-	- network-manager <unfixed> (bug #1145199)
+	- network-manager 1.58.1-1 (bug #1145199)
 	[trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
 	[bookworm] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
 	[bullseye] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
@@ -11993,6 +11993,7 @@ CVE-2026-19685 (NetworkManager did not apply the private_user restriction to the
 	NOTE: Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)
 	NOTE: The introducing commit is part of the patchseries for CVE-2025-9615
 	NOTE: Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3e70060abd721d9a347f42b2ba68e6e
+	NOTE: Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/15aa1a8963ee014f5eb8306b305b158293c10643 (1.58.1)
 CVE-2026-9033 (An unauthenticated attacker with network access to the captive portal  ...)
 	NOT-FOR-US: TPLink
 CVE-2026-8717



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a14120c67fe4f8200f580adaa33e3520d9487bb0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a14120c67fe4f8200f580adaa33e3520d9487bb0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/b815e9e7/attachment.htm>


More information about the debian-security-tracker-commits mailing list